2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48853CRITICAL9.5An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a...
CVE-2024-48850HIGH7.5Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue aff...
CVE-2024-54188MEDIUM5.3Infoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read arbitrary files with root a...
CVE-2024-12093MEDIUM6.8An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and ...
CVE-2024-25010HIGH8.8Ericsson RAN Compute and Site Controller 6610 contains in certain configurations a high severity vulnerability where imp...
CVE-2024-9544MEDIUM6.4The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,...
CVE-2024-57529MEDIUM6.1Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary c...
CVE-2024-56428MEDIUM5.5The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the C...
CVE-2024-23337MEDIUM6.5jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning va...
CVE-2024-56429HIGH7.7itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users t...
CVE-2024-42922MEDIUM6.5AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.
CVE-2024-12561MEDIUM6.1The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versi...
CVE-2024-45641MEDIUM6.5IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate val...
CVE-2024-53359HIGH7.5An issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request.
CVE-2024-5878MEDIUM6.4Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled SimpleLightbox Jav...
CVE-2024-33939MEDIUM5.3Authentication Bypass Using an Alternate Path or Channel vulnerability in masteriyo Masteriyo - LMS learning-management-...
CVE-2024-55063HIGH8.8Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execut...
CVE-2024-51106MEDIUM4.6A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation...
CVE-2024-4878Rejected reason: Unused CVE record, incorrectly reserved
CVE-2024-13965Rejected reason: wrong year
CVE-2024-13964Rejected reason: wrong year
CVE-2024-13613HIGH7.5The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-47893MEDIUM6.5Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or w...
CVE-2024-40120MEDIUM6.5seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_sto...
CVE-2024-53827HIGH7.5Ericsson Packet Core Controller (PCC) contains a vulnerability where an attacker sending a large volume of specially cra...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now